All news
Security
28 September 2026

Critical security updates released for Citrix NetScaler devices

Citrix has released emergency security patches for NetScaler ADC and Gateway to address three critical vulnerabilities. These flaws are currently being exploited by attackers to gain unauthorised access to corporate networks.

What this means for your business

Small and medium businesses using Citrix for remote work must apply these updates immediately to prevent network intrusion. If your business uses NetScaler and has not patched since Sunday, your systems are at high risk of compromise.

Overview of the Citrix vulnerabilities

Citrix has issued a set of emergency updates for its NetScaler ADC (Application Delivery Controller) and NetScaler Gateway products. These devices are used by many UK businesses to manage network traffic and provide secure remote access to employees.

Security researchers have identified three critical vulnerabilities, alongside five other serious flaws, that allow attackers to bypass security controls. These vulnerabilities are classified as 'zero-day' exploits, meaning they were discovered by attackers before a fix was available. Reports indicate that these flaws are now being used in active attacks to breach business networks.

Technical details and risks

The most severe of these flaws involve unauthenticated remote code execution. This means an attacker can run commands on the device from the internet without needing a username or password. Once an attacker gains control of a NetScaler device, they can often access the wider company network, steal data, or deploy ransomware.

Because these devices sit at the edge of your network, they are a primary target for automated scanning tools used by cybercriminals. The Register reports that the frequency of these attacks has increased since the vulnerabilities were disclosed on Sunday.

Recommended actions for business owners

If your business uses Citrix for remote access, you should verify with your IT department or service provider that your firmware is up to date. The following versions contain the necessary fixes:

  • NetScaler ADC and NetScaler Gateway 14.1-30.37 and later
  • NetScaler ADC and NetScaler Gateway 13.1-55.25 and later
  • NetScaler ADC and NetScaler Gateway 13.0-92.35 and later

At this stage, there are no known workarounds that provide the same level of protection as the official patches. If your devices cannot be updated immediately, they should be taken offline to prevent unauthorised access. It is also advisable to review system logs for any unusual administrative activity occurring over the last 48 hours, as this may indicate a breach has already taken place.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.